You're using an older version of Internet Explorer that is no longer supported. Please update your browser.

SOC 2 Manager, Audit & Certification, Deloitte Global Technology

Full Time
4 days ago
Job Type:Permanent
Reference code:125605
Primary Location:Toronto, ON
All Available Locations:Toronto, ON; Burlington, ON; Calgary, AB; Edmonton, AB; Montreal, QC; Ottawa, ON; Quebec City, QC; Vancouver, BC; Victoria, BC; Windsor, ON; Winnipeg, MB

Our Purpose

At Deloitte, we are driven to inspire and help our people, organization, communities, and country to thrive. Our Purpose is to build a better future by accelerating and expanding access to knowledge. Purpose defines who we are and gives us reason to exist as an organization.
By living our Purpose, we will make an impact that matters.
  • Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.
  • Experience a firm where wellness matters.
  • Be expected to share your ideas and to make them a reality.

This role supports audits and assessment programs of DT Cybersecurity Governance, Risk & Compliance, Audit & Certification team which includes risk management, audits, and assessments for on premises as well as cloud hosted IT applications and infrastructure.

This position is specifically responsible for helping drive SOC 2 audits and manage the day-to-day responsibilities of gathering evidence, scheduling resources, coordinating with control owners and external auditors, and identifying potential audit issues/operational improvements. Role is to also understand and assess technology and operational risks related to internal and cloud technology solutions and at times, provide input to DT personnel on appropriate controls to address audit risks. The position will also work with external and internal auditors, serving as liaison between DT and non- DT auditees, gathering and presenting evidence as required.

Key Tasks / Essential Job Functions:
  • Understand technology controls, testing of controls, and supporting evidence.
  • Understand technology controls that impact on premises and cloud technology, operational risk to the Deloitte Technology organization as well as related laws, regulations, and industry standards, specifically related to internal and cloud technology solutions.
  • Recommend policies, standards, procedures, and controls to assure the confidentiality, integrity, and availability of the information technology environment for on premises as well as cloud hosted IT applications and infrastructure.
  • Manage audit gaps; identify those n the organization responsible for remediating or closing audit findings, negotiate dates for closure, and track/report progress.
  • Represent DT related to internal and external assessments and/or audits of information technology systems and processes, interpret results, develop and communicate recommendations to management.
  • Participate in appropriate opportunities for continuing education, seminars, and participation in field-related professional organizations to remain current on developments as an information security profession.
  • Work with the appropriate Information Security, Office of General Counsel, Risk Management, and leadership to determine scope of onsite visits, audits, and assessments as defined by contracts and regulatory requirements.
  • Develop and recommend appropriate information security policies, standards, procedures, checklists, and guidelines using generally recognized security concepts tailored to meet the requirements of the organization for on premises as well as cloud hosted IT applications and infrastructure.
  • Identify and document specific security issues, propose resolution options, and interpret matters from the perspective of involved stakeholders.
  • Make decisions on day-to-day task assignments to the team.
  • May lead projects and in some cases, manage staff.

About the team

Cybersecurity vigilantly protects Deloitte and client data. The team leads a strategic cyber risk program that adapts to a rapidly changing threat landscape, changes in business strategies, risks, and vulnerabilities. Using situational awareness, threat intelligence, and building a security culture across the organization, the team helps to protect the Deloitte brand.

Enough about us, let's talk about you

Required Qualifications:

  • Bachelor's degree in Computer Science, Business Administration, Information Systems, Accounting or equivalent educational or professional experience and/or qualifications.
  • Minimum 6 years of directly related experience in the following: managing information technology audits, assessments, remediation management, creating, leading, and managing risk assessment programs.
  • Minimum 2 years of experience with various industry standard frameworks such as: SSAE 18 SOC 2, HITRUST, CSA, CCM.

Preferred Qualifications:
  • Industry certification (e.g., CPA, CISA, CISSP, CISM etc.)
  • Experience leading IT internal audit, external audits, and or service organization control reporting and activities.
  • Solid understanding of IT general controls and activities.
  • Familiarity with privacy laws, data protection/security regulations, and cloud security framework.
  • Possess a general understanding of IT security technologies, including network, application and database security, access management and cloud security.
  • Negotiation skills to obtain commitments to remediate risks and vulnerabilities from leadership of other teams.
  • Excellent communication, listening, and facilitation skills (preferred).
  • Excellent time management and related organizational skills, including appropriate sense of urgency, a proactive approach, and a suitable ability to anticipate and manage project lifecycle events, issues, and obstacles (preferred).
  • Very good understanding and experience with cloud technologies and security controls (preferred).

Total Rewards

The salary range for this position is $85,000 - $156,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.

Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. Some representative examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, 38+ days off (including 10 firm-wide closures known as "Deloitte Days"), flexible work arrangements and a hybrid work structure.

Our promise to our people: Deloitte is where potential comes to life.

Be yourself, and more.
We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance.
You shape how we make impact.
Diverse perspectives and life experiences make us better. Whoever you are and wherever you're from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute. Be the leader you want to be.
Be the leader you want to be
Some guide teams, some change culture, some build essential expertise. We offer opportunities and experiences that support your continuing growth as a leader.
Have as many careers as you want.
We are uniquely able to offer you new challenges and roles - and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors. Our TVP is about relationships - between leaders and their people, the firm and its people, peers, and within in our communities.

The next step is yours

At Deloitte, we are all about doing business inclusively - that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our AccessAbility Action Plan , Reconciliation Action Plan and the BlackNorth Initiative .
We encourage you to connect with us at if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis).
By applying to this job you will be assessed against the Deloitte Global Talent Standards. We've designed these standards to provide our clients with a consistent and exceptional Deloitte experience globally.
Deloitte Canada has 30 offices with representation across most of the country. We acknowledge our offices reside on traditional, treaty and unceded territories as part of Turtle Island and is still home to many First Nations, Métis, and Inuit peoples. We are all Treaty people.

Job Segment: Cyber Security, Developer, Internal Audit, Information Security, Compliance, Security, Technology, Finance, Legal
Management and Executive

The #1 Podcast for Jobseekers

Latest Episode:

#81 - Wealthsimple - Developing an Engineering Career in FinTech

Interested in jobs like this?

Sign up for email alerts
Get job alerts

About Deloitte

Deloitte, one of Canada's leading professional services firms, provides audit, tax, consulting, and financial advisory services. Deloitte LLP, an Ontario limited liability partnership, is the ...

Read More
Management and Consulting
5001-10,000 employees